CVE-2018-16858
CVSS v3
9.8
CRITICAL
Score EPSS
67.3 %
probabilité d’exploitation au 2026-10-05
CISA KEV
Non
exploitation connue
Exploitation
—
statut SSVC
Description
It was found that libreoffice before versions 6.0.7 and 6.1.3 was vulnerable to a directory traversal attack which could be used to execute arbitrary macros bundled with a document. An attacker could craft a document, which when opened by LibreOffice, would execute a Python method from a script in any arbitrary file system location, specified relative to the LibreOffice install location.
Détails techniques
- Publiée le
- 2019-03-25
- Exploit-DB
- EDB-46727
Questions fréquentes
Qu’est-ce que CVE-2018-16858 ?
It was found that libreoffice before versions 6.0.7 and 6.1.3 was vulnerable to a directory traversal attack which could be used to execute arbitrary macros bundled with a document. An attacker could craft a document, which when opened by LibreOffice, would execute a Python method from a script in any arbitrary file system location, specified relative to the LibreOffice install location.
CVE-2018-16858 est-elle activement exploitée ?
Aucune exploitation active de CVE-2018-16858 n’est confirmée. Son score EPSS était de 67.3 % au 2026-10-05, soit la probabilité estimée d’exploitation dans les 30 prochains jours.
Quel est le score CVSS de CVE-2018-16858 ?
CVE-2018-16858 a un score de base CVSS v3 de 9.8 (gravité CRITICAL).
CVE-2018-16858 touche-t-elle votre environnement ?
Utilisez isMalicious pour vérifier si l’une de vos IP ou l’un de vos domaines est associé aux IOC de cette vulnérabilité.
Sans carte bancaire · 50 vérifications gratuites par mois · Clé API gratuite
Autres vulnérabilités 2018 à trier
Classées par probabilité d’exploitation (EPSS).